Weaknesses of type CWE-770

1,861 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2026-1850HIGHAn authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplificationEPSS 0.3%CVE-2021-47771MEDIUMRDP Manager 4.9.9.3 - Denial-of-Service (PoC)EPSS 0.3%CVE-2022-42312MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2025-68659MEDIUMDiscourse has DoS vulnerability in username change endpointEPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2026-88359MEDIUMlibfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containEPSS 0.2%CVE-2025-64529LOWSpiceDB's WriteRelationships fails silently if payload is too bigEPSS 0.2%CVE-2025-4437MEDIUMCri-o: large /etc/passwd file may lead to denial of serviceEPSS 0.2%CVE-2025-36122MEDIUMIBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automaticEPSS 0.2%CVE-2026-55996MEDIUMUnauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agentEPSS 0.2%CVE-2022-40885MEDIUMBento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.EPSS 0.2%CVE-2025-48467MEDIUMDenial of Service via Malformed Modbus PacketsEPSS 0.2%CVE-2025-14299HIGHImproper Content-Length Validation in HTTPS Requests on Tapo C200EPSS 0.2%CVE-2026-78321MEDIUMDJI Drone HTTP Media Server Denial of Service via Connection Pool ExhaustionEPSS 0.2%CVE-2026-2325MEDIUMImproper Input Validation in MS Teams Meetings API HandlerEPSS 0.2%CVE-2026-14539MEDIUMDenial of Service via Unrestricted Payload Buffering in MCP ToolboxEPSS 0.2%CVE-2023-52518MEDIUMBluetooth: hci_codec: Fix leaking content of local_codecsEPSS 0.2%CVE-2026-20608MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iEPSS 0.2%CVE-2024-34027HIGHf2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lockEPSS 0.2%CVE-2025-20141HIGHCisco IOS XR Software Release 7.9.2 Denial of Service VulnerabillityEPSS 0.2%